6.28 Security / Infrastructure Integrity / Anti-Abuse / Bot Protection / Stability Suite
150 checks in Schema, Local, Trust, Deep Audit. Automated
Its subsection has a live automated checker in the engine.
SSL/TLS Configuration, Certificate Health & Transport Security
| ID | Check | Passes when | Weight | Runs |
|---|
| 6.28.01 | Validate SSL certificate valid, unexpired, correctly installed | Valid | Critical | Deterministic |
| 6.28.02 | Validate TLS 1.2+ enforced (no TLS 1.0/1.1) | Enforced | Critical | Deterministic |
| 6.28.03 | Validate no weak ciphers enabled | Strong | Critical | Deterministic |
| 6.28.04 | Validate HSTS header present (Strict-Transport-Security) | Present | Heavy | Deterministic |
| 6.28.05 | Validate HSTS preload eligibility | Eligible | Heavy | Deterministic |
| 6.28.06 | Validate certificate chain complete (no missing intermediate) | Complete | Heavy | Deterministic |
| 6.28.07 | Validate certificate uses SHA-256+ signature | Present | Heavy | Deterministic |
| 6.28.08 | Validate OCSP stapling enabled | Enabled | Medium | Deterministic |
| 6.28.09 | Validate no mixed-content warnings | Clean | Medium | Deterministic |
| 6.28.10 | Validate redirects to HTTPS consistently (301) | Strong | Medium | Deterministic |
Security Headers — CSP / Xss / Clickjacking / Sandboxing
| ID | Check | Passes when | Weight | Runs |
|---|
| 6.28.11 | Validate Content-Security-Policy (CSP) implemented | Present | Critical | Deterministic |
| 6.28.12 | Validate CSP blocks inline scripts (no unsafe-inline) | Strong | Critical | Deterministic |
| 6.28.13 | Validate X-Frame-Options or frame-ancestors prevents clickjacking | Present | Critical | Deterministic |
| 6.28.14 | Validate X-XSS-Protection configured properly | Present | Heavy | Deterministic |
| 6.28.15 | Validate X-Content-Type-Options = nosniff | Present | Heavy | Deterministic |
| 6.28.16 | Validate Referrer-Policy secure (strict-origin-when-cross-origin or stricter) | Secure | Heavy | Deterministic |
| 6.28.17 | Validate Permissions-Policy configured correctly | Correct | Medium | Deterministic |
| 6.28.18 | Validate COOP/COEP/CORP headers (Cross-origin isolation) | Present | Medium | Deterministic |
| 6.28.19 | Validate iframe sandbox attributes properly set | Present | Medium | Deterministic |
| 6.28.20 | Validate no overly permissive CSP directives | Clean | Medium | Deterministic |
Bot Protection, Rate Limiting & Anti-Automation
| ID | Check | Passes when | Weight | Runs |
|---|
| 6.28.21 | Validate rate limiting enabled (API + application) | Present | Heavy | Deterministic |
| 6.28.22 | Validate bot fingerprinting / behavioral analysis present | Present | Heavy | Deterministic |
| 6.28.23 | Validate CAPTCHA / proof-of-work used on abuse-sensitive endpoints | Present | Heavy | Deterministic |
| 6.28.24 | Validate login endpoints protected against brute force | Protected | Medium | Deterministic |
| 6.28.25 | Validate WAF blocks malicious user agents | Present | Medium | Deterministic |
| 6.28.26 | Validate automated scraping signals monitored | Active | Medium | Deterministic |
| 6.28.27 | Validate JavaScript challenges where appropriate | Present | Medium | Deterministic |
| 6.28.28 | Validate API keys protected (not client-exposed) | Secure | Medium | Deterministic |
| 6.28.29 | Validate no open endpoints leaking data | Clean | Medium | Deterministic |
| 6.28.30 | Validate anti-bot heuristics do not affect real users | Balanced | Medium | Deterministic |
Firewall Rules, Waf Config, IP Blocking & Traffic Anomaly Detection
| ID | Check | Passes when | Weight | Runs |
|---|
| 6.28.31 | Validate WAF (Web Application Firewall) enabled | Enabled | Heavy | Deterministic |
| 6.28.32 | Validate WAF signatures updated | Updated | Heavy | Deterministic |
| 6.28.33 | Validate WAF blocks SQLi, XSS, RCE patterns | Present | Heavy | Deterministic |
| 6.28.34 | Validate IP reputation filtering enabled | Present | Medium | Deterministic |
| 6.28.35 | Validate anomaly detection rules active (DDoS, flood, scraper) | Active | Medium | Deterministic |
| 6.28.36 | Validate geo-blocking / geo-fencing configured if relevant | Correct | Medium | Deterministic |
| 6.28.37 | Validate firewall does not block legitimate crawlers | Balanced | Medium | Deterministic |
| 6.28.38 | Validate rate-limit bursts handled gracefully | Correct | Medium | Deterministic |
| 6.28.39 | Validate transparent fallback for false-positives | Present | Medium | Deterministic |
| 6.28.40 | Validate WAF logs monitored & alerts configured | Active | Medium | Deterministic |
Authentication Security, Session Integrity & Access Control
| ID | Check | Passes when | Weight | Runs |
|---|
| 6.28.41 | Validate password hashing uses Argon2/Bcrypt/PBKDF2 (not MD5/SHA1) | Secure | Heavy | Deterministic |
| 6.28.42 | Validate MFA (2FA) available for privileged accounts | Present | Heavy | Deterministic |
| 6.28.43 | Validate session cookies HttpOnly + Secure + SameSite=Lax/Strict | Secure | Heavy | Deterministic |
| 6.28.44 | Validate session fixation protections present | Present | Medium | Deterministic |
| 6.28.45 | Validate admin panel access restricted by IP or firewall | Restricted | Medium | Deterministic |
| 6.28.46 | Validate no default passwords or default admin URLs | Clean | Medium | Deterministic |
| 6.28.47 | Validate brute-force lockout on login | Present | Medium | Deterministic |
| 6.28.48 | Validate OAuth/OpenID tokens validated correctly | Correct | Medium | Deterministic |
| 6.28.49 | Validate role-based access control enforced | Enforced | Medium | Deterministic |
| 6.28.50 | Compute partial Security score for Chunk 1 | Complete | Medium | Deterministic |
Server Hardening, Patch Management & System Integrity
| ID | Check | Passes when | Weight | Runs |
|---|
| 6.28.51 | Validate server OS fully patched | Updated | Heavy | Deterministic |
| 6.28.52 | Validate no outdated server packages | Clean | Heavy | Deterministic |
| 6.28.53 | Validate SSH hardened (key‑based auth, no root login) | Hardened | Heavy | Deterministic |
| 6.28.54 | Validate SSH running on non‑standard port (optional but recommended) | Present | Heavy | Deterministic |
| 6.28.55 | Validate firewall (UFW/iptables/Cloudflare rules) active | Active | Heavy | Deterministic |
| 6.28.56 | Validate OS kernel free of critical CVEs | Clean | Medium | Deterministic |
| 6.28.57 | Validate fail2ban (or equivalent) enabled | Present | Medium | Deterministic |
| 6.28.58 | Validate file permissions hardened (600/700 for key configs) | Hardened | Medium | Deterministic |
| 6.28.59 | Validate logging/monitoring of root access | Active | Medium | Deterministic |
| 6.28.60 | Validate cron jobs secure (no insecure scripts) | Clean | Medium | Deterministic |
Dependency Vulnerability Scanning & Package Security
| ID | Check | Passes when | Weight | Runs |
|---|
| 6.28.61 | Validate automated vulnerability scanning active (Snyk, Dependabot, etc.) | Active | Heavy | Deterministic |
| 6.28.62 | Validate no high‑severity dependencies installed | Clean | Heavy | Deterministic |
| 6.28.63 | Validate package manager lockfiles up to date | Updated | Heavy | Deterministic |
| 6.28.64 | Validate dependency bloat minimized | Low | Medium | Deterministic |
| 6.28.65 | Validate only production dependencies shipped to server | Correct | Medium | Deterministic |
| 6.28.66 | Validate unused libraries removed | Clean | Medium | Deterministic |
| 6.28.67 | Validate devtools not exposed publicly | Clean | Medium | Deterministic |
| 6.28.68 | Validate no abandoned/unmaintained libraries | Clean | Medium | Deterministic |
| 6.28.69 | Validate npm/pip/etc. integrity checks (checksums) | Enabled | Medium | Deterministic |
| 6.28.70 | Validate package update frequency stable & monitored | Active | Medium | Deterministic |
CDN Security, Ddos Defense, Edge Protections & Mitigation Logic
| ID | Check | Passes when | Weight | Runs |
|---|
| 6.28.71 | Validate CDN DDoS protection enabled (Layer 3/4/7) | Enabled | Heavy | Deterministic |
| 6.28.72 | Validate CDN bot‑fight mode / anti‑automation (if available) | Active | Heavy | Deterministic |
| 6.28.73 | Validate CDN firewall rules correct & restrictive | Strong | Heavy | Deterministic |
| 6.28.74 | Validate CDN TLS offload not reducing security | Secure | Medium | Deterministic |
| 6.28.75 | Validate CDN cache poisoning protections active | Present | Medium | Deterministic |
| 6.28.76 | Validate CDN WAF signature updates frequent | Updated | Medium | Deterministic |
| 6.28.77 | Validate CDN challenge logic does not affect real users | Balanced | Medium | Deterministic |
| 6.28.78 | Validate CDN edge workers safe & not introducing vulnerabilities | Safe | Medium | Deterministic |
| 6.28.79 | Validate CDN rate‑limit thresholds correct | Correct | Medium | Deterministic |
| 6.28.80 | Validate origin IP fully hidden | Hidden | Medium | Deterministic |
DNS Security, Domain Protection & Record Integrity
| ID | Check | Passes when | Weight | Runs |
|---|
| 6.28.81 | Validate DNSSEC enabled (if registrar supports it) | Present | Heavy | Deterministic |
| 6.28.82 | Validate SPF record correct & strict | Correct | Heavy | Deterministic |
| 6.28.83 | Validate DKIM configured correctly | Strong | Heavy | Deterministic |
| 6.28.84 | Validate DMARC policy set (quarantine or reject) | Strong | Heavy | Deterministic |
| 6.28.85 | Validate CAA record present limiting certificate authorities | Present | Medium | Deterministic |
| 6.28.86 | Validate no dangling DNS records | Clean | Medium | Deterministic |
| 6.28.87 | Validate MX records correct | Correct | Medium | Deterministic |
| 6.28.88 | Validate no wildcard DNS unless needed | Clean | Medium | Deterministic |
| 6.28.89 | Validate DNS response time stable | Stable | Medium | Deterministic |
| 6.28.90 | Validate zone transfers (AXFR) disabled | Disabled | Medium | Deterministic |
Abuse Prevention, Spam Filtering & Form Security
| ID | Check | Passes when | Weight | Runs |
|---|
| 6.28.91 | Validate all forms protected (CSRF tokens) | Present | Heavy | Deterministic |
| 6.28.92 | Validate spam protection active (Akismet, reCAPTCHA, hCaptcha, etc.) | Active | Heavy | Deterministic |
| 6.28.93 | Validate form validation server‑side (not only JS) | Present | Heavy | Deterministic |
| 6.28.94 | Validate honeypot fields implemented | Present | Medium | Deterministic |
| 6.28.95 | Validate email injection protections active | Present | Medium | Deterministic |
| 6.28.96 | Validate file upload endpoints fully sanitized | Secure | Medium | Deterministic |
| 6.28.97 | Validate forms rate‑limited | Present | Medium | Deterministic |
| 6.28.98 | Validate error messages not leaking internal info | Clean | Medium | Deterministic |
| 6.28.99 | Validate form endpoints protected from enumeration | Protected | Medium | Deterministic |
| 6.28.100 | Compute partial Security score for Chunk 2 | Complete | Medium | Deterministic |
Server Stability, Uptime, Failover & Redundancy
| ID | Check | Passes when | Weight | Runs |
|---|
| 6.28.101 | Validate monitored uptime > 99.9% | >99.9% | Heavy | Deterministic |
| 6.28.102 | Validate redundancy across availability zones | Present | Heavy | Deterministic |
| 6.28.103 | Validate automated failover in case of primary failure | Functional | Heavy | Deterministic |
| 6.28.104 | Validate active health checks for backend services | Present | Heavy | Deterministic |
| 6.28.105 | Validate no single points of failure (hardware or software) | Clean | Medium | Deterministic |
| 6.28.106 | Validate load balancer configured correctly | Correct | Medium | Deterministic |
| 6.28.107 | Validate auto-scaling enabled (CPU/memory thresholds) | Present | Medium | Deterministic |
| 6.28.108 | Validate error rate monitored and alerts configured | Active | Medium | Deterministic |
| 6.28.109 | Validate maintenance windows scheduled appropriately | Scheduled | Medium | Deterministic |
| 6.28.110 | Validate downtime notifications configured | Present | Medium | Deterministic |
Application Security, Input Validation & Framework Safety
| ID | Check | Passes when | Weight | Runs |
|---|
| 6.28.111 | Validate no SQL injection vectors | Clean | Heavy | Deterministic |
| 6.28.112 | Validate no XSS vectors (stored or reflected) | Clean | Heavy | Deterministic |
| 6.28.113 | Validate parameterized queries used | Present | Heavy | Deterministic |
| 6.28.114 | Validate ORM protections enabled (if used) | Enabled | Heavy | Deterministic |
| 6.28.115 | Validate input validation covers all user inputs | Complete | Medium | Deterministic |
| 6.28.116 | Validate sanitization present for text, HTML, URLs | Present | Medium | Deterministic |
| 6.28.117 | Validate deserialization safe (no insecure object parsing) | Safe | Medium | Deterministic |
| 6.28.118 | Validate SSRF protections present (URL allowlists) | Present | Medium | Deterministic |
| 6.28.119 | Validate CSRF tokens rotate per session | Present | Medium | Deterministic |
| 6.28.120 | Validate CORS configured correctly (no wide-open origins) | Correct | Medium | Deterministic |
Data Security, Storage Protection & Access Logging
| ID | Check | Passes when | Weight | Runs |
|---|
| 6.28.121 | Validate encryption at rest enabled | Enabled | Heavy | Deterministic |
| 6.28.122 | Validate no sensitive data stored unencrypted | Clean | Heavy | Deterministic |
| 6.28.123 | Validate database access restricted (IP/firewall-based) | Restricted | Heavy | Deterministic |
| 6.28.124 | Validate backups encrypted | Encrypted | Heavy | Deterministic |
| 6.28.125 | Validate backup frequency meets SLA | Meets SLA | Medium | Deterministic |
| 6.28.126 | Validate backup integrity checked regularly | Verified | Medium | Deterministic |
| 6.28.127 | Validate logs protected from tampering | Protected | Medium | Deterministic |
| 6.28.128 | Validate audit logs include admin actions | Present | Medium | Deterministic |
| 6.28.129 | Validate access logs rotate & archived securely | Present | Medium | Deterministic |
| 6.28.130 | Validate no sensitive logs exposed publicly | Clean | Medium | Deterministic |
Monitoring, Alerting, Incident Response & Security Operations
| ID | Check | Passes when | Weight | Runs |
|---|
| 6.28.131 | Validate monitoring platform active (Datadog, New Relic, etc.) | Active | Heavy | Deterministic |
| 6.28.132 | Validate SIEM (Security Information & Event Management) configured | Present | Heavy | Deterministic |
| 6.28.133 | Validate anomaly alerts configured (CPU, traffic, errors) | Active | Heavy | Deterministic |
| 6.28.134 | Validate incident response plan documented | Present | Heavy | Deterministic |
| 6.28.135 | Validate incident roles assigned (owner, approver, responder) | Present | Medium | Deterministic |
| 6.28.136 | Validate simulated incident drills performed | Present | Medium | Deterministic |
| 6.28.137 | Validate alerts integrated with on‑call rota | Present | Medium | Deterministic |
| 6.28.138 | Validate alert fatigue avoided (no useless alerts) | Clean | Medium | Deterministic |
| 6.28.139 | Validate escalation paths defined clearly | Present | Medium | Deterministic |
| 6.28.140 | Validate time-to-resolution metrics monitored | Monitored | Medium | Deterministic |
Final Security, Bot Protection & Infrastructure Integrity Scoring
| ID | Check | Passes when | Weight | Runs |
|---|
| 6.28.141 | Validate infrastructure fully hardened | Hardened | Heavy | Deterministic |
| 6.28.142 | Validate DNS, TLS, headers & WAF alignment perfect | Strong | Heavy | Deterministic |
| 6.28.143 | Validate no unmitigated vulnerabilities remain | Clean | Heavy | Deterministic |
| 6.28.144 | Validate logs + monitoring provide complete visibility | Complete | Medium | Deterministic |
| 6.28.145 | Validate backup + failover strategy reliable | Strong | Medium | Deterministic |
| 6.28.146 | Validate security documentation comprehensive | Present | Medium | Deterministic |
| 6.28.147 | Validate team aware of security processes | Yes | Medium | Deterministic |
| 6.28.148 | Validate AI interpretability of security signals | High | Medium | Deterministic |
| 6.28.149 | Validate no contradictions across domain/server/app layers | Clean | Medium | Deterministic |
| 6.28.150 | Compute full Security / Integrity composite score | >= 90% | Critical | Deterministic |
← 6.26 Trust / E-E-A-T / Brand Authority / Social Proof / Reputation Suite6.29 Privacy / Compliance / Data Policy / User Rights / AI-Transparency Suite →
Run these checks on your site
A Deep Audit scores every check here that applies to your page, then an AI pass of up to 150 checks. Included on Pro and Ultra, or $9 for one audit.
See plans
Machine-readable: catalog totals and the
full catalog as JSON (IDs, section, weight, status).